Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2532▼ 361 respecto a la semana anterior
Críticas / altas1338▲ 69 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 6 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
231 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.8) | 0.14% | — | AMD Secure ProcessorAI | 10/2/2026 | 17/6/2026 | Insufficient input parameter sanitization in AMD Secure Processor (ASP) Boot Loader (legacy recovery mode only) could allow an attacker to write out-of-bounds to corrupt Secure DRAM potentially resulting in denial of service. | |
| Aplazada | Media (6.8) | 0.14% | — | AMD ProcessorsAI | 10/2/2026 | 17/6/2026 | Improper handling of overlap between the segmented reverse map table (RMP) and system management mode (SMM) memory could allow a privileged attacker corrupt or partially infer SMM memory resulting in loss of integrity or confidentiality. | |
| Aplazada | Baja (1.8) | 0.15% | — | AMD Secure ProcessorAI | 10/2/2026 | 17/6/2026 | Improper syscall input validation in ASP (AMD Secure Processor) may force the kernel into reading syscall parameter values from its own memory space allowing an attacker to infer the contents of the kernel memory leading to potential information disclosure. | |
| Aplazada | Baja (1.8) | 0.14% | — | Intel ProcessorAI | 10/2/2026 | 17/6/2026 | Improper handling of values in the microcode flow for some Intel(R) Processor Family may allow an escalation of privilege. Startup code and smm adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack… | |
| Aplazada | Media (5.4) | 0.11% | — | Intel Processor Identification UtilityAI | 11/11/2025 | 17/6/2026 | Uncontrolled search path for the Intel(R) Processor Identification Utility before version 8.0.43 within Ring 3: User Applications may allow an escalation of privilege. System software adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege. This result may… | |
| Aplazada | Media (5.4) | 0.11% | — | Intel Processor Identification UtilityAI | 11/11/2025 | 17/6/2026 | Incorrect default permissions for the Intel(R) Processor Identification Utility before version 8.0.43 within Ring 3: User Applications may allow an escalation of privilege. System software adversary with an authenticated user combined with a high complexity attack may enable local code execution. This result may… | |
| Aplazada | Alta (8.5) | 0.24% | — | Intel Processor Identification UtilityAI | 11/11/2025 | 17/6/2026 | Use of unmaintained third party components for some Intel(R) Processor Identification Utility before version 8.0.43 within Ring 3: User Applications may allow an escalation of privilege. System software adversary with an authenticated user combined with a low complexity attack may enable escalation of privilege. This… | |
| Analizada | Crítica (9.8) | 0.40% | — | Qualcomm Apq8017 FirmwareQualcomm Apq8064au FirmwareQualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 Firmware+223 | 24/9/2025 | 17/6/2026 | Memory corruption when the UE receives an RTP packet from the network, during the reassembly of NALUs. | |
| Analizada | Alta (8.2) | 0.26% | — | Qualcomm Apq8017 FirmwareQualcomm Apq8064au FirmwareQualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 Firmware+223 | 24/9/2025 | 25/9/2026 | Information disclosure while decoding RTP packet received by UE from the network, when payload length mentioned is greater than the available buffer length. | |
| Analizada | Alta (8.2) | 0.26% | — | Qualcomm Sm8750 FirmwareQualcomm Sm8750p FirmwareQualcomm Sm8850 FirmwareQualcomm Sm8850p Firmware+169 | 24/9/2025 | 25/9/2026 | Information disclosure when UE receives the RTP packet from the network, while decoding and reassembling the fragments from RTP packet. | |
| Aplazada | Alta (8.5) | 0.34% | — | Subtitle ProcessorAI | 20/8/2025 | 16/6/2026 | Subtitle Processor 7.7.1 contains a buffer overflow vulnerability in its .m3u file parser. When a crafted playlist file is opened, the application converts input to Unicode and copies it to a fixed-size stack buffer without proper bounds checking. This allows an attacker to overwrite the Structured Exception Handler… | |
| Aplazada | Media (4.5) | 0.14% | — | Intel Xeon 6 ProcessorsAIIntel SGXAIIntel TDXAI | 12/8/2025 | 17/6/2026 | Improperly implemented security check for standard in the DDRIO configuration for some Intel(R) Xeon(R) 6 Processors when using Intel(R) SGX or Intel(R) TDX may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Aplazada | Alta (7) | 0.14% | — | Intel Xeon ProcessorsAI | 12/8/2025 | 17/6/2026 | Insufficient control flow management in the Alias Checking Trusted Module (ACTM) firmware for some Intel(R) Xeon(R) processors may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Aplazada | Alta (7.3) | 0.14% | — | Intel ProcessorsAI | 12/8/2025 | 17/6/2026 | Improper Isolation or Compartmentalization in the stream cache mechanism for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Aplazada | Alta (7) | 0.15% | — | Intel Xeon Processor FirmwareAI | 12/8/2025 | 17/6/2026 | Improper buffer restrictions for some Intel(R) Xeon(R) Processor firmware with SGX enabled may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Aplazada | Media (5.6) | 0.34% | — | AMD ProcessorsAI | 8/7/2025 | 17/6/2026 | A transient execution vulnerability in some AMD processors may allow an attacker to infer data in the L1D cache, potentially resulting in the leakage of sensitive information across privileged boundaries. | |
| Aplazada | Media (5.6) | 0.49% | — | AMD ProcessorsAI | 8/7/2025 | 17/6/2026 | A transient execution vulnerability in some AMD processors may allow an attacker to infer data from previous stores, potentially resulting in the leakage of privileged information. | |
| Aplazada | Baja (3.8) | 0.18% | — | AMD ProcessorsAI | 8/7/2025 | 17/6/2026 | A transient execution vulnerability in some AMD processors may allow a user process to infer TSC_AUX even when such a read is disabled, potentially resulting in information leakage. | |
| Aplazada | Baja (3.8) | 0.30% | — | AMD ProcessorsAI | 8/7/2025 | 17/6/2026 | A transient execution vulnerability in some AMD processors may allow a user process to infer the control registers speculatively even if UMIP feature is enabled, potentially resulting in information leakage. | |
| Aplazada | Crítica (9.1) | 0.46% | — | Open Source Risc V ProcessorAI | 1/7/2025 | 17/6/2026 | Improper mstatus.SUM bit retention (non-zero) in Open-Source RISC-V Processor commit f517abb violates privileged spec constraints, enabling potential physical memory access attacks. | |
| Aplazada | Alta (7.9) | 0.18% | — | AMD ASPAIAMD Crypto Co-processorAI | 10/6/2025 | 17/6/2026 | Improper register access control in ASP may allow a privileged attacker to perform unauthorized access to ASP’s Crypto Co-Processor (CCP) registers from x86 resulting in potential loss of control of cryptographic key pointer/index leading to loss of integrity or confidentiality. | |
| Analizada | Alta (8.2) | 0.30% | — | Qualcomm Apq8017 FirmwareQualcomm Apq8064au FirmwareQualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 Firmware+230 | 3/6/2025 | 17/6/2026 | Information disclosure when an invalid RTCP packet is received during a VoLTE/VoWiFi IMS call. | |
| Analizada | Alta (8.2) | 0.24% | — | Qualcomm Apq8017 FirmwareQualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+221 | 3/6/2025 | 17/6/2026 | Information disclosure may occur while processing goodbye RTCP packet from network. | |
| Analizada | Alta (8.2) | 0.24% | — | Qualcomm Apq8017 FirmwareQualcomm Apq8064au FirmwareQualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 Firmware+230 | 3/6/2025 | 17/6/2026 | Information disclosure may occur while decoding the RTP packet with invalid header extension from network. | |
| Aplazada | Media (5.7) | 0.19% | — | Intel Core Processors 10th GenerationAI | 13/5/2025 | 17/6/2026 | Exposure of sensitive information caused by shared microarchitectural predictor state that influences transient execution for some Intel(R) Core™ processors (10th Generation) may allow an authenticated user to potentially enable information disclosure via local access. |